DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-102278: CVE-2026-102278: Stack-Based Denial of Service via Uncontrolled Recursion in brace-expansion

CVE-2026-102278: Stack-Based Denial of Service via Uncontrolled Recursion in brace-expansion

Vulnerability ID: CVE-2026-102278
CVSS Score: 7.5
Published: 2026-09-29

A stack-based Denial of Service (DoS) vulnerability via uncontrolled recursion in the brace-expansion library prior to versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11 allows unauthenticated remote attackers to trigger native stack exhaustion, terminating the Node.js process via a crafted payload containing deeply nested brace groups.

TL;DR

Uncontrolled recursion in nested brace groups allows unauthenticated attackers to crash the Node.js process via a stack overflow using compact (~6KB) inputs.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-674
  • Attack Vector: Network (Unauthenticated)
  • CVSS: 7.5 (High)
  • EPSS: 0.0035 (26th percentile)
  • Impact: Denial of Service (Process Termination)
  • Exploit Status: Proof-of-Concept
  • KEV Status: Not Listed

Affected Systems

  • Node.js applications processing untrusted shell-like patterns or glob vectors via brace-expansion.
  • Libraries utilizing brace-expansion transitively, such as older versions of minimatch or glob parsers.
  • brace-expansion: < 1.1.20 (Fixed in: 1.1.20)
  • brace-expansion: >= 2.0.0, < 2.1.6 (Fixed in: 2.1.6)
  • brace-expansion: >= 3.0.0, < 3.0.8 (Fixed in: 3.0.8)
  • brace-expansion: >= 4.0.0, < 5.0.11 (Fixed in: 5.0.11)

Code Analysis

Commit: 935d78f

Bound nesting recursion using EXPANSION_MAX_DEPTH in TypeScript module.

Commit: de84f14

Add maxDepth configuration and depth monitoring on nested expands for ESM.

Commit: 1efee7c

Implement recursion depths and legacy ES5 compatibility variables.

Exploit Details

  • GitHub Advisory: Security advisory details containing vulnerability mechanics and reproduction methods.

Mitigation Strategies

  • Upgrade dependency to patched versions across all active branches.
  • Sanitize and restrict input pattern complexity at application entry points.
  • Employ process managers (e.g., PM2) to ensure auto-restart capability upon crash events.

Remediation Steps:

  1. Identify vulnerable versions of brace-expansion using 'npm ls brace-expansion' or Software Composition Analysis.
  2. Force update of deep dependencies using package manager resolutions or overrides if transitive.
  3. In npm projects using version 5, execute: npm install brace-expansion@5.0.11
  4. Verify the application does not crash when supplied with deeply nested brace patterns.

References


Read the full report for CVE-2026-102278 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)